Junglewise Threat Intelligence

CVE-2025-39757: Linux Kernel ALSA out-of-bounds read in usb-audio UAC3 descriptors

CVE-2025-39757 · Severity: high · CVSS 7.1 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's USB audio driver (ALSA). The system fails to properly check the size of data provided by USB audio devices using the UAC3 standard. A malicious or compromised USB device could provide specially crafted data to cause the system to read memory outside of intended boundaries, potentially leading to a system crash or the exposure of sensitive information.

Technical details

An out-of-bounds (OOB) read vulnerability (CWE-125) exists in the Linux kernel's ALSA usb-audio driver within the 'sound/usb/stream.c' component. The root cause is a lack of validation for UAC3 (USB Audio Class 3) cluster segment descriptors; specifically, the driver does not verify if the declared descriptor lengths match the actual data or fit within allocated buffer sizes. An attacker with physical access or the ability to emulate a USB device can provide malicious firmware descriptors to trigger OOB accesses. This can result in a denial of service (system crash) or information disclosure. Patches have been released across multiple stable kernel branches (4.19.y through 6.16.y).

Affected products

  • Linux Linux Kernel 4.19 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-08-14: other: Patch authored by Takashi Iwai
  • 2025-09-11: disclosed: CVE published
  • 2026-01-09: advisory: NIST/NVD enrichment completed

References

Related threats